[KLUG Members] LDAP via URL

Adam Tauno Williams adam at morrison-ind.com
Tue Jun 28 18:48:14 EDT 2005


> >There is no way to hide a password in an URL, except of course to use LDAP
> over >SSL (ldaps://)
> I will check this option... curl will be the method I am looking at which
> you  mentioned. (Would be interesting to see what in the world Mozilla 
> displays when you point it at a LDAP URL.)

http://www.faqs.org/rfcs/rfc2255.html - is the definitive source for LDAP URL
info.  It even contains examples.

> >There is no URL socket.  An ldap:/// ... url communicates using native LDAP
> >protocol. 
> Ja, but it has a socket open / listening on the NIC to make that happen,
> thus what I was talking about. There is also that, what was it, AppSocket? 
> where it skips going to the NIC but that obviously does not work across the 
> wire.

A single server can listen on multiple sockets, both IP and domain socket.

> I was thinking here that the main LDAP daemon could be configured for
> AppSocket
> only and has "all" of the data in it. A second LDAP daemon (on the same box)
> could be configured to listen on the NIC, and receive a replica of just the
> bit
> of the entire database which is needed via URL access. All this assuming the
> "if you build it they will come" and that more than one app wants to use the
> LDAP services.


More information about the Members mailing list